Xpdf
149 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Xpdf, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
Xpdf CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 149 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical12
- High38
- Medium82
- Low13
Latest CVEs
The 15 most recently published vulnerabilities affecting Xpdf.
- CVE-2026-85458Divide-by-zero in Xpdf 4.06 due to zero-height Type 3 glyph—
- CVE-2026-4407Out-of-bounds array write in Xpdf 4.06 due to missing validation—
- CVE-2025-11896Stack overflow in Xpdf 4.05 due to object loop in PDF CMap—
- CVE-2025-3154Out-of-bounds array write due to invalid VerticesPerRow in Xpdf 4.05—
- CVE-2025-2574Out-of-bounds array write in Xpdf 4.05 due to incorrect integer overflow checking2.9
- CVE-2024-7868Uninitialized variable in Xpdf 4.05 due to invalid JPEG header8.2
- CVE-2024-7867Integer overflow and divide-by-zero in Xpdf 4.05 due to bogus page box coordinates6.2
- CVE-2024-7866Stack overflow in Xpdf 4.05 due to object loop in PDF pattern5.5
- CVE-2024-4976Out-of-bounds array write in Xpdf 4.05 due to missing object type check5.5
- CVE-2024-4568Stack overflow in Xpdf 4.05 due to object loop in PDF resources2.9
- CVE-2024-4141Out-of-bounds array write in Xpdf 4.05 due to incorrect bounds check2.9
- CVE-2024-3900Out-of-bounds stack array write in Xpdf 4.05 due to missing zero check2.9
- CVE-2024-3248Stack overflow in Xpdf 4.05 due to object loop in attachments2.9
- CVE-2024-3247Stack overflow in Xpdf 4.05 due to object loop in PDF object stream2.9
- CVE-2024-2971Out-of-bounds array access due to negative object numbers in indirect references in Xpdf 4.052.9
Product grouping is registry-driven, with AI assist and human review. How it works